Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2011-0752)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-3394)
Ruby Improper Input Validation Vulnerability (CVE-2008-3657)
Moodle Other Vulnerability (CVE-2004-1425)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-26071)